CVE-2020-13985: Integer Overflow
Published Dec 11, 2020
·Updated
An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rplremoveheader in net/rpl/rpl-ext-header.c.
Affected Software
9 affected components
Contiki-os Contiki<=3.0
Multiple (open source) uIP-Contiki-OS (end-of-life [EOL]), Version 3.0 and prior
Multiple (open source) uIP-Contiki-NG, Version 4.5 and prior
Multiple (open source) uIP (EOL), Version 1.0 and prior
Multiple (open source) open-iscsi, Version 2.1.12 and prior
Multiple (open source) picoTCP-NG, Version 1.7.0 and prior
Multiple (open source) picoTCP (EOL), Version 1.7.0 and prior
Multiple (open source) FNET, Version 4.6.3
Multiple (open source) Nut/Net, Version 5.1 and prior
Event History
Dec 11, 2020
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
Description
Aug 4, 2024
Data Sourced
via ICS·12:40 PM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-13985?
The severity of CVE-2020-13985 is high with a CVSS score of 7.5.
2
What is the affected software of CVE-2020-13985?
The affected software of CVE-2020-13985 is Contiki OS version up to 3.0.
3
What is the description of CVE-2020-13985?
CVE-2020-13985 is a memory corruption vulnerability in the uIP TCP/IP stack component of Contiki OS.
4
How can I fix CVE-2020-13985?
To fix CVE-2020-13985, it is recommended to update Contiki OS to a version higher than 3.0.
5
Are there any references for CVE-2020-13985?
Yes, you can find references for CVE-2020-13985 at the following links: [Link 1](https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01), [Link 2](https://www.kb.cert.org/vuls/id/815128).